SlideShare a Scribd company logo
1 of 18
THE GENERAL DATA PROTECTION
REGULATION (“GDPR”)
Tsutomu L. Johnson
November 7, 2017
Salt Lake City
parsonsbehle.com
Cybersecurity Series from Parsons Behle & Latimer
2
 Before we get into the GDPR, we have to understand the
European Data Protection Directive.
– Leveraging the fundamental freedom of privacy in Europe, the
Directive established the following:
• Controller and Processor relationships;
• Broadly defined the terms Personal Data and Processing;
• Created contractual obligations for suppliers and vendors to preserve
privacy;
• Created a framework for multinational organizations to process
information within the organization; and
• Created the first data localization rules.
History
3
 The GDPR is organized s follows:
– General Provisions (Art. 1-4)
– Privacy Principles (Art. 5-11)
– Data Subjects’ Rights (Art. 12-23)
– Controller and Processor Obligations (Art. 24-43)
– International Data Transfers (Art. 44-50)
– Remedies, Liability, and Penalties (Art. 77-84)
GDPR at a Glance
4
 Definitions:
– Personal Data: ANY information that can be used to directly or indirectly identify a
natural person.
– Processing: Any operation or set of operations performed on Personal Data whether by
automated means or not.
– Controller: The entity or person which alone, or with others, determines the purposes
and means of the Processing Personal data.
– Processor: An entity or person which Processes Personal Data on behalf of a Controller.
– Profiling: Any type of automated processing to evaluate a natural person for things like a
person’s performance at work, economic situation, health, personal preferences,
interests, reliability, behavior, location, or movements.
– Pseudonymization: Processing Personal Data in such a way that it can no longer be
attributed to a specific person without the use of additional information which is protected
by an organization’s technical and organizational measures. Example: encryption.
General Provisions
5
 Territorial Scope:
– The GDPR applies to:
• Controllers and Processors not established in the EU that Process,
• Personal Data belonging to people in the EU,
• where activities are related to:
– Offering goods or services, irrespective of whether a payment is required; or
– Monitoring of behavior as far as that behavior takes place in the EU.
General Provisions
6
 Processing Personal Data
– Personal Data must be Processed lawfully, fairly, and transparently.
– Controllers can only collect Personal Data:
• For a specific, explicit, and legitimate purpose and cannot Process Personal Data in a
manner incompatible with that purpose.
• Where it is adequate, relevant, and limited to what is necessary in relation to the
purpose it was gathered.
• If the Personal Data is accurate.
• If kept in a form permitting identification of people for no longer than is necessary for
the purpose the Personal Data was initially gathered.
• If it is Processed in a manner that ensures appropriate security and protection against
unauthorized use or unlawful Processing.
Privacy Principles
7
 Lawfulness of Processing: The following are the limited situations where it is lawful
to Process Personal Data:
– If a person gives consent.
• If Processing is based on consent, the Controller must demonstrate that a person has freely given
consent that is specific and informed. The consent must demonstrate clear affirmative agreement to
Process Personal Data.
• Note: a person can withdraw consent at any time and force a Controller to stop Processing the
person’s Personal Data.
– For a contract wherein the EU resident is a party to the contract or is about to enter into a
contract with the Controller.
– Legal compliance.
– Protecting a person’s vital interests.
– For Processing carried out in the public’s interest.
– For the Controller’s legitimate interests that don’t disrupt a person’s fundamental
rights to privacy.
Privacy Principles
8
 Controllers must:
– Notify people about how the Controller Processes Personal Data before Processing
Personal Data.
– Give people the ability to access relevant Personal Data Processed by the Controller.
– Allow people to access their Personal data and correct missing, incomplete, or inaccurate
information.
– Erase information about people upon their request if that information is no longer
necessary for the purpose which it was gathered.
– Restrict Processing.
– Provide all Personal Data the Controller has about a person to that person in a structured
and commonly used, machine-readable format.
– Allow individuals to object to Processing by automated means, Processing for direct
marketing, and Processing carried out in the Controller’s legitimate interests.
Data Subjects’ Rights
9
 Controllers:
– Must implement appropriate technical and organizational
measures to protect Personal Data.
– Incorporate privacy principles such as pseudonymization and
data minimization into all Processing activities.
– Designate, in writing, a representative in the EU if the Controller
is not located in the EU but does business in the EU.
Controller and Processor Obligations
10
 Processors:
– Must contractually guarantee the implementation of appropriate
technical and organizational measures to protect Personal Data.
– Will only Process Personal Data with the Controller’s written
authorization.
– Follow specific contractual guidelines such as: ensuring people are
authorized to Process Personal Data on the Controller’s behalf,
implementing appropriate security measures, and assisting the
Controller with the Controller’s compliance obligations.
Controller and Processor Obligations
11
 Joint Obligations:
– Create a record of Processing listing the Controller’s: contact details, purpose for
Processing, categories of Personal Data Processed, categories of recipients, where
information transfers, a general description of technological and organizational
safeguards.
– Cooperate with DPAs.
– Implement appropriate codes of conduct and technical and organizational measures to
ensure security measures are tailored to risks presented by Processing.
– Notify DPAs and affected individuals about data breach events.
– Carry out Data Protection Impact Assessments (“DPIA”) and consult with DPAs where a
DPIA reveals a new project, process, or technology could result in high risk to a person in
the EU.
– Potentially appoint a Data Protection Officer within the organization.
Controller and Processor Obligations
12
 Generally, Personal Data cannot leave the EU.
 Controllers and Processors can transfer Personal Data out of
the EU if the recipient agrees to appropriate safeguards and
people in the EU can enforce their rights against the
recipients.
– Appropriate safeguards include: binding corporate rules, standard
data protection clauses, and approved codes of conduct.
– Contractual clauses between the Controller and Processor suffice,
but need pre-approval by a DPA.
International Data Transfers
13
 People in Europe have the right to sue Controllers and Processors.
 Controllers can be sued for damage caused by Processing which infringes the GDPR.
 Processors are liable for damage caused by Processing where it has not complied with the
GDPR or acted without their Controller’s approval.
 Where more than one Controller or Processor is liable for damages, each Controller or
Processor is held liable for the entire damage amount. After payment, the Controllers and
Processors sort out who among them are responsible for their share of fault.
 Penalties:
– For failing to comply with Controller and Processor obligations: €10,000,000 or 2% of annual
revenue.
– For failing to comply with basic principles for Processing, Data Subject Rights, International Data
Transfers, Member State laws, and a DPA’s orders: €20,000,000 or 4% of annual revenue.
Remedies, Liability, and Penalties
14
 We are on a short time frame for compliance. Starting
today, organizations have about 200 days to adopt
technical and organizational policies to comply with the
GDPR.
What Does This Mean?
15
 0-30 days:
– Determine whether your organization Processes Personal Data from people in the
EU.
– Determine where that information comes from, what that information is, how you
presently secure that information, and whether you share that information with other
Controllers, Processors, and other organizations internationally.
– Review the GDPR, write down its obligations.
– Determine whether status-quo operations satisfy those obligations and identify gaps.
– Analyze whether current security processes meet the GDPR’s technical and
organizational requirements. If not, develop a security plan to achieve compliance.
– Evaluate current contracts with Controllers and subcontractors. Determine what
language should go into contracts with both groups of entities and create a timeframe
for revising those contracts.
What Can You Do?
16
 30 – 90 days:
– Create a Privacy Office and nominate a data privacy officer.
– Conduct data mapping exercises to determine how your organization Processes and
secures information.
– Setup a DPIA process that incorporates Privacy by Design principles. Use this
process to recommend new technology to comply with GDPR security requirements.
– Create an Incident Response Plan.
– Create a data transfer agreement form for internal and external Controllers and
Processors.
– Evaluate Controller and Processor contracts and determine which contracts need
revisions to comply with the GDPR.
– Create Notice and Consent forms compliant with the GDPR.
– Setup processes to comply with Data Subject Rights.
What Can You Do?
17
 90 – 180 days:
– Roll out security plan.
– Create a Record of Processing; identify the legal basis for
processing, and revise contract/processes to find a legal basis
for Processing activities. Leverage the data mapping exercise
to tie into this exercise.
What Can You Do?
18
 My next presentation is on November 14th, I will be doing
a tabletop exercise for incident response with HPE and
others.
 If you have any questions, please contact me at:
Tsutomu Johnson
Tjohnson@parsonsbehle.com
801.536.6903
Thank You

More Related Content

What's hot

Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...IISPEastMids
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!Fintan Swanton
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliantSiddharth Ram Dinesh
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsPECB
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overviewJane Lambert
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...Cvent
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationVicky Dallas
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSAUlf Mattsson
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPRTim Hyman LLB
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Andrew Sharpe
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitjoshquarrie
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationJake DiMare
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumConstantine Karbaliotis
 

What's hot (20)

GDPR-Overview
GDPR-OverviewGDPR-Overview
GDPR-Overview
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Get you and your business GDPR ready
Get you and your business GDPR readyGet you and your business GDPR ready
Get you and your business GDPR ready
 
Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...Be careful what you wish for: the great Data Protection law reform - Lilian E...
Be careful what you wish for: the great Data Protection law reform - Lilian E...
 
GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!GDPR - Fail to Prepare, Prepare to Fail!
GDPR - Fail to Prepare, Prepare to Fail!
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
GDPR Demystified
GDPR DemystifiedGDPR Demystified
GDPR Demystified
 
EU GDPR (training)
EU GDPR (training)  EU GDPR (training)
EU GDPR (training)
 
How to get started with being GDPR compliant
How to get started with being GDPR compliantHow to get started with being GDPR compliant
How to get started with being GDPR compliant
 
Data Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New RegulationsData Privacy Trends in 2021: Compliance with New Regulations
Data Privacy Trends in 2021: Compliance with New Regulations
 
GDPR Introduction and overview
GDPR Introduction and overviewGDPR Introduction and overview
GDPR Introduction and overview
 
General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...General Data Protection Regulations (GDPR): Do you understand it and are you ...
General Data Protection Regulations (GDPR): Do you understand it and are you ...
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
Gdpr action plan - ISSA
Gdpr action plan - ISSAGdpr action plan - ISSA
Gdpr action plan - ISSA
 
The Essential Guide to GDPR
The Essential Guide to GDPRThe Essential Guide to GDPR
The Essential Guide to GDPR
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Intercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkitIntercity technology - GDPR your training toolkit
Intercity technology - GDPR your training toolkit
 
GDPRR: The Key Changes
GDPRR: The Key ChangesGDPRR: The Key Changes
GDPRR: The Key Changes
 
The Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection RegulationThe Meaning and Impact of the General Data Protection Regulation
The Meaning and Impact of the General Data Protection Regulation
 
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada SymposiumImpact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
Impact of GDPR on Canada May 2016 - Presented at IAPP Canada Symposium
 

Similar to The General Data Protection Regulation ("GDPR")

Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Acquia
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European unionRohana K Amarakoon
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?VILT
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance IT Governance Ltd
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessOmo Osagiede
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistChristina Gagnier
 
The GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so farThe GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so farPECB
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupThe Pathway Group
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceIT Governance Ltd
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowTerry Gorry
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceCobweb
 
Data protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and BirdData protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and BirdCoadec
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaperJim Wilson
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 

Similar to The General Data Protection Regulation ("GDPR") (20)

Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)Understanding the EU's new General Data Protection Regulation (GDPR)
Understanding the EU's new General Data Protection Regulation (GDPR)
 
General data protection regulation - European union
General data protection regulation  - European unionGeneral data protection regulation  - European union
General data protection regulation - European union
 
GDPR - Are you ready?
GDPR - Are you ready?GDPR - Are you ready?
GDPR - Are you ready?
 
Gdpr action plan
Gdpr action plan Gdpr action plan
Gdpr action plan
 
The first steps towards GDPR compliance 
The first steps towards GDPR compliance The first steps towards GDPR compliance 
The first steps towards GDPR compliance 
 
GDPR: Key Article Overview
GDPR: Key Article OverviewGDPR: Key Article Overview
GDPR: Key Article Overview
 
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readinessGeneral Data Protection Regulation (GDPR) - Moving from confusion to readiness
General Data Protection Regulation (GDPR) - Moving from confusion to readiness
 
European Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation ChecklistEuropean Union Privacy Law - General Data Protection Regulation Checklist
European Union Privacy Law - General Data Protection Regulation Checklist
 
The GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so farThe GDPR: Common misunderstandings and lessons learned so far
The GDPR: Common misunderstandings and lessons learned so far
 
An Overview of GDPR
An Overview of GDPR An Overview of GDPR
An Overview of GDPR
 
An Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway GroupAn Overview of GDPR by Pathway Group
An Overview of GDPR by Pathway Group
 
The GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for complianceThe GDPR’s impact on your business and preparing for compliance
The GDPR’s impact on your business and preparing for compliance
 
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should KnowThe General Data Protection Regulation (GDPR) in Ireland-What You Should Know
The General Data Protection Regulation (GDPR) in Ireland-What You Should Know
 
GDPR: Your Journey to Compliance
GDPR: Your Journey to ComplianceGDPR: Your Journey to Compliance
GDPR: Your Journey to Compliance
 
GDPR SECURITY ISSUES
GDPR SECURITY ISSUESGDPR SECURITY ISSUES
GDPR SECURITY ISSUES
 
Data protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and BirdData protection for Lend.io - legal analysis by Bird and Bird
Data protection for Lend.io - legal analysis by Bird and Bird
 
GDPR
GDPRGDPR
GDPR
 
Prepare Your Firm for GDPR
Prepare Your Firm for GDPRPrepare Your Firm for GDPR
Prepare Your Firm for GDPR
 
GDPRIBMWhitePaper
GDPRIBMWhitePaperGDPRIBMWhitePaper
GDPRIBMWhitePaper
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 

More from Parsons Behle & Latimer

Navigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable AccommodationNavigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable AccommodationParsons Behle & Latimer
 
Navigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable AccommodationNavigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable AccommodationParsons Behle & Latimer
 
Preventing and Responding to Workplace Violence and the New HB 324
Preventing and Responding to Workplace Violence and the New HB 324Preventing and Responding to Workplace Violence and the New HB 324
Preventing and Responding to Workplace Violence and the New HB 324Parsons Behle & Latimer
 
Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...
Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...
Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...Parsons Behle & Latimer
 
Employee Life Cycle I: HR Law Issues Pre-employment
Employee Life Cycle I: HR Law Issues Pre-employmentEmployee Life Cycle I: HR Law Issues Pre-employment
Employee Life Cycle I: HR Law Issues Pre-employmentParsons Behle & Latimer
 
Employee Life Cycle II: HR Law Issues During Employment
Employee Life Cycle II: HR Law Issues During EmploymentEmployee Life Cycle II: HR Law Issues During Employment
Employee Life Cycle II: HR Law Issues During EmploymentParsons Behle & Latimer
 
Conducting Effective Workplace Investigations
Conducting Effective Workplace InvestigationsConducting Effective Workplace Investigations
Conducting Effective Workplace InvestigationsParsons Behle & Latimer
 
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAConfidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAParsons Behle & Latimer
 
The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...
The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...
The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...Parsons Behle & Latimer
 
Inflation Reduction Act - Broad Observations
Inflation Reduction Act - Broad ObservationsInflation Reduction Act - Broad Observations
Inflation Reduction Act - Broad ObservationsParsons Behle & Latimer
 
Social Media: What's Not to Like About Social Media in the Workplace?
Social Media: What's Not to Like About Social Media in the Workplace?Social Media: What's Not to Like About Social Media in the Workplace?
Social Media: What's Not to Like About Social Media in the Workplace?Parsons Behle & Latimer
 
Everything You Want to Ask Your Lawyer But Are Afraid to Ask
Everything You Want to Ask Your Lawyer But Are Afraid to AskEverything You Want to Ask Your Lawyer But Are Afraid to Ask
Everything You Want to Ask Your Lawyer But Are Afraid to AskParsons Behle & Latimer
 
Privacy in the Workplace: How Much Snooping is Legal and Proper?
Privacy in the Workplace: How Much Snooping is Legal and Proper?Privacy in the Workplace: How Much Snooping is Legal and Proper?
Privacy in the Workplace: How Much Snooping is Legal and Proper?Parsons Behle & Latimer
 
Every Case Really is a Story: Four State and Federal Caselaw Stories and Lessons
Every Case Really is a Story: Four State and Federal Caselaw Stories and LessonsEvery Case Really is a Story: Four State and Federal Caselaw Stories and Lessons
Every Case Really is a Story: Four State and Federal Caselaw Stories and LessonsParsons Behle & Latimer
 
Breaking HR Law News: Legislative and Regulatory Update
Breaking HR Law News: Legislative and Regulatory UpdateBreaking HR Law News: Legislative and Regulatory Update
Breaking HR Law News: Legislative and Regulatory UpdateParsons Behle & Latimer
 

More from Parsons Behle & Latimer (20)

Navigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable AccommodationNavigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable Accommodation
 
Labor Issues for the Non-Union Employer
Labor Issues for the Non-Union EmployerLabor Issues for the Non-Union Employer
Labor Issues for the Non-Union Employer
 
Navigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable AccommodationNavigating the ADA: Case Studies on Reasonable Accommodation
Navigating the ADA: Case Studies on Reasonable Accommodation
 
Preventing and Responding to Workplace Violence and the New HB 324
Preventing and Responding to Workplace Violence and the New HB 324Preventing and Responding to Workplace Violence and the New HB 324
Preventing and Responding to Workplace Violence and the New HB 324
 
Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...
Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...
Employee Life Cycle III: Termination Trepidation - Identifying and Avoiding t...
 
Employee Life Cycle I: HR Law Issues Pre-employment
Employee Life Cycle I: HR Law Issues Pre-employmentEmployee Life Cycle I: HR Law Issues Pre-employment
Employee Life Cycle I: HR Law Issues Pre-employment
 
Employee Life Cycle II: HR Law Issues During Employment
Employee Life Cycle II: HR Law Issues During EmploymentEmployee Life Cycle II: HR Law Issues During Employment
Employee Life Cycle II: HR Law Issues During Employment
 
Conducting Effective Workplace Investigations
Conducting Effective Workplace InvestigationsConducting Effective Workplace Investigations
Conducting Effective Workplace Investigations
 
Regulatory Hot Topics
Regulatory Hot TopicsRegulatory Hot Topics
Regulatory Hot Topics
 
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAConfidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
 
The Corporate Transparency Act
The Corporate Transparency ActThe Corporate Transparency Act
The Corporate Transparency Act
 
The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...
The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...
The Major Questions Doctrine: A Review of the Supreme Court Decision in West ...
 
Inflation Reduction Act - Broad Observations
Inflation Reduction Act - Broad ObservationsInflation Reduction Act - Broad Observations
Inflation Reduction Act - Broad Observations
 
Social Media: What's Not to Like About Social Media in the Workplace?
Social Media: What's Not to Like About Social Media in the Workplace?Social Media: What's Not to Like About Social Media in the Workplace?
Social Media: What's Not to Like About Social Media in the Workplace?
 
Everything You Want to Ask Your Lawyer But Are Afraid to Ask
Everything You Want to Ask Your Lawyer But Are Afraid to AskEverything You Want to Ask Your Lawyer But Are Afraid to Ask
Everything You Want to Ask Your Lawyer But Are Afraid to Ask
 
The ADA and Bosses Behaving Badly
The ADA and Bosses Behaving BadlyThe ADA and Bosses Behaving Badly
The ADA and Bosses Behaving Badly
 
Common Mistakes Employers Make
Common Mistakes Employers MakeCommon Mistakes Employers Make
Common Mistakes Employers Make
 
Privacy in the Workplace: How Much Snooping is Legal and Proper?
Privacy in the Workplace: How Much Snooping is Legal and Proper?Privacy in the Workplace: How Much Snooping is Legal and Proper?
Privacy in the Workplace: How Much Snooping is Legal and Proper?
 
Every Case Really is a Story: Four State and Federal Caselaw Stories and Lessons
Every Case Really is a Story: Four State and Federal Caselaw Stories and LessonsEvery Case Really is a Story: Four State and Federal Caselaw Stories and Lessons
Every Case Really is a Story: Four State and Federal Caselaw Stories and Lessons
 
Breaking HR Law News: Legislative and Regulatory Update
Breaking HR Law News: Legislative and Regulatory UpdateBreaking HR Law News: Legislative and Regulatory Update
Breaking HR Law News: Legislative and Regulatory Update
 

Recently uploaded

Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargainingbartzlawgroup1
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书irst
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理Airst S
 
5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdfTodd Spodek
 
Performance of contract-1 law presentation
Performance of contract-1 law presentationPerformance of contract-1 law presentation
Performance of contract-1 law presentationKhushdeep Kaur
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdfBritto Valan
 
Reason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in IndiaReason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in IndiaYash
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptJosephCanama
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理ss
 
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理e9733fc35af6
 
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理e9733fc35af6
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubham Wadhonkar
 
一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理Fir La
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxIshikaChauhan30
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理F La
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理e9733fc35af6
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYJulian Scutts
 
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理ss
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理bd2c5966a56d
 
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理e9733fc35af6
 

Recently uploaded (20)

Understanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective BargainingUnderstanding the Role of Labor Unions and Collective Bargaining
Understanding the Role of Labor Unions and Collective Bargaining
 
一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书一比一原版(USC毕业证书)南加州大学毕业证学位证书
一比一原版(USC毕业证书)南加州大学毕业证学位证书
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf
 
Performance of contract-1 law presentation
Performance of contract-1 law presentationPerformance of contract-1 law presentation
Performance of contract-1 law presentation
 
Hely-Hutchinson v. Brayhead Ltd .pdf
Hely-Hutchinson v. Brayhead Ltd         .pdfHely-Hutchinson v. Brayhead Ltd         .pdf
Hely-Hutchinson v. Brayhead Ltd .pdf
 
Reason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in IndiaReason Behind the Success of Law Firms in India
Reason Behind the Success of Law Firms in India
 
Code_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.pptCode_Ethics of_Mechanical_Engineering.ppt
Code_Ethics of_Mechanical_Engineering.ppt
 
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
一比一原版(RMIT毕业证书)皇家墨尔本理工大学毕业证如何办理
 
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
一比一原版(KPU毕业证书)加拿大昆特兰理工大学毕业证如何办理
 
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
一比一原版(OhioStateU毕业证书)美国俄亥俄州立大学毕业证如何办理
 
Shubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptxShubh_Burden of proof_Indian Evidence Act.pptx
Shubh_Burden of proof_Indian Evidence Act.pptx
 
一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理一比一原版(Warwick毕业证书)华威大学毕业证如何办理
一比一原版(Warwick毕业证书)华威大学毕业证如何办理
 
judicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptxjudicial remedies against administrative actions.pptx
judicial remedies against administrative actions.pptx
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
 
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
一比一原版(纽大毕业证书)美国纽约大学毕业证如何办理
 
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURYA SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
A SHORT HISTORY OF LIBERTY'S PROGREE THROUGH HE EIGHTEENTH CENTURY
 
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
一比一原版(UNSW毕业证书)新南威尔士大学毕业证如何办理
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
一比一原版(Carleton毕业证书)加拿大卡尔顿大学毕业证如何办理
 

The General Data Protection Regulation ("GDPR")

  • 1. THE GENERAL DATA PROTECTION REGULATION (“GDPR”) Tsutomu L. Johnson November 7, 2017 Salt Lake City parsonsbehle.com Cybersecurity Series from Parsons Behle & Latimer
  • 2. 2  Before we get into the GDPR, we have to understand the European Data Protection Directive. – Leveraging the fundamental freedom of privacy in Europe, the Directive established the following: • Controller and Processor relationships; • Broadly defined the terms Personal Data and Processing; • Created contractual obligations for suppliers and vendors to preserve privacy; • Created a framework for multinational organizations to process information within the organization; and • Created the first data localization rules. History
  • 3. 3  The GDPR is organized s follows: – General Provisions (Art. 1-4) – Privacy Principles (Art. 5-11) – Data Subjects’ Rights (Art. 12-23) – Controller and Processor Obligations (Art. 24-43) – International Data Transfers (Art. 44-50) – Remedies, Liability, and Penalties (Art. 77-84) GDPR at a Glance
  • 4. 4  Definitions: – Personal Data: ANY information that can be used to directly or indirectly identify a natural person. – Processing: Any operation or set of operations performed on Personal Data whether by automated means or not. – Controller: The entity or person which alone, or with others, determines the purposes and means of the Processing Personal data. – Processor: An entity or person which Processes Personal Data on behalf of a Controller. – Profiling: Any type of automated processing to evaluate a natural person for things like a person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. – Pseudonymization: Processing Personal Data in such a way that it can no longer be attributed to a specific person without the use of additional information which is protected by an organization’s technical and organizational measures. Example: encryption. General Provisions
  • 5. 5  Territorial Scope: – The GDPR applies to: • Controllers and Processors not established in the EU that Process, • Personal Data belonging to people in the EU, • where activities are related to: – Offering goods or services, irrespective of whether a payment is required; or – Monitoring of behavior as far as that behavior takes place in the EU. General Provisions
  • 6. 6  Processing Personal Data – Personal Data must be Processed lawfully, fairly, and transparently. – Controllers can only collect Personal Data: • For a specific, explicit, and legitimate purpose and cannot Process Personal Data in a manner incompatible with that purpose. • Where it is adequate, relevant, and limited to what is necessary in relation to the purpose it was gathered. • If the Personal Data is accurate. • If kept in a form permitting identification of people for no longer than is necessary for the purpose the Personal Data was initially gathered. • If it is Processed in a manner that ensures appropriate security and protection against unauthorized use or unlawful Processing. Privacy Principles
  • 7. 7  Lawfulness of Processing: The following are the limited situations where it is lawful to Process Personal Data: – If a person gives consent. • If Processing is based on consent, the Controller must demonstrate that a person has freely given consent that is specific and informed. The consent must demonstrate clear affirmative agreement to Process Personal Data. • Note: a person can withdraw consent at any time and force a Controller to stop Processing the person’s Personal Data. – For a contract wherein the EU resident is a party to the contract or is about to enter into a contract with the Controller. – Legal compliance. – Protecting a person’s vital interests. – For Processing carried out in the public’s interest. – For the Controller’s legitimate interests that don’t disrupt a person’s fundamental rights to privacy. Privacy Principles
  • 8. 8  Controllers must: – Notify people about how the Controller Processes Personal Data before Processing Personal Data. – Give people the ability to access relevant Personal Data Processed by the Controller. – Allow people to access their Personal data and correct missing, incomplete, or inaccurate information. – Erase information about people upon their request if that information is no longer necessary for the purpose which it was gathered. – Restrict Processing. – Provide all Personal Data the Controller has about a person to that person in a structured and commonly used, machine-readable format. – Allow individuals to object to Processing by automated means, Processing for direct marketing, and Processing carried out in the Controller’s legitimate interests. Data Subjects’ Rights
  • 9. 9  Controllers: – Must implement appropriate technical and organizational measures to protect Personal Data. – Incorporate privacy principles such as pseudonymization and data minimization into all Processing activities. – Designate, in writing, a representative in the EU if the Controller is not located in the EU but does business in the EU. Controller and Processor Obligations
  • 10. 10  Processors: – Must contractually guarantee the implementation of appropriate technical and organizational measures to protect Personal Data. – Will only Process Personal Data with the Controller’s written authorization. – Follow specific contractual guidelines such as: ensuring people are authorized to Process Personal Data on the Controller’s behalf, implementing appropriate security measures, and assisting the Controller with the Controller’s compliance obligations. Controller and Processor Obligations
  • 11. 11  Joint Obligations: – Create a record of Processing listing the Controller’s: contact details, purpose for Processing, categories of Personal Data Processed, categories of recipients, where information transfers, a general description of technological and organizational safeguards. – Cooperate with DPAs. – Implement appropriate codes of conduct and technical and organizational measures to ensure security measures are tailored to risks presented by Processing. – Notify DPAs and affected individuals about data breach events. – Carry out Data Protection Impact Assessments (“DPIA”) and consult with DPAs where a DPIA reveals a new project, process, or technology could result in high risk to a person in the EU. – Potentially appoint a Data Protection Officer within the organization. Controller and Processor Obligations
  • 12. 12  Generally, Personal Data cannot leave the EU.  Controllers and Processors can transfer Personal Data out of the EU if the recipient agrees to appropriate safeguards and people in the EU can enforce their rights against the recipients. – Appropriate safeguards include: binding corporate rules, standard data protection clauses, and approved codes of conduct. – Contractual clauses between the Controller and Processor suffice, but need pre-approval by a DPA. International Data Transfers
  • 13. 13  People in Europe have the right to sue Controllers and Processors.  Controllers can be sued for damage caused by Processing which infringes the GDPR.  Processors are liable for damage caused by Processing where it has not complied with the GDPR or acted without their Controller’s approval.  Where more than one Controller or Processor is liable for damages, each Controller or Processor is held liable for the entire damage amount. After payment, the Controllers and Processors sort out who among them are responsible for their share of fault.  Penalties: – For failing to comply with Controller and Processor obligations: €10,000,000 or 2% of annual revenue. – For failing to comply with basic principles for Processing, Data Subject Rights, International Data Transfers, Member State laws, and a DPA’s orders: €20,000,000 or 4% of annual revenue. Remedies, Liability, and Penalties
  • 14. 14  We are on a short time frame for compliance. Starting today, organizations have about 200 days to adopt technical and organizational policies to comply with the GDPR. What Does This Mean?
  • 15. 15  0-30 days: – Determine whether your organization Processes Personal Data from people in the EU. – Determine where that information comes from, what that information is, how you presently secure that information, and whether you share that information with other Controllers, Processors, and other organizations internationally. – Review the GDPR, write down its obligations. – Determine whether status-quo operations satisfy those obligations and identify gaps. – Analyze whether current security processes meet the GDPR’s technical and organizational requirements. If not, develop a security plan to achieve compliance. – Evaluate current contracts with Controllers and subcontractors. Determine what language should go into contracts with both groups of entities and create a timeframe for revising those contracts. What Can You Do?
  • 16. 16  30 – 90 days: – Create a Privacy Office and nominate a data privacy officer. – Conduct data mapping exercises to determine how your organization Processes and secures information. – Setup a DPIA process that incorporates Privacy by Design principles. Use this process to recommend new technology to comply with GDPR security requirements. – Create an Incident Response Plan. – Create a data transfer agreement form for internal and external Controllers and Processors. – Evaluate Controller and Processor contracts and determine which contracts need revisions to comply with the GDPR. – Create Notice and Consent forms compliant with the GDPR. – Setup processes to comply with Data Subject Rights. What Can You Do?
  • 17. 17  90 – 180 days: – Roll out security plan. – Create a Record of Processing; identify the legal basis for processing, and revise contract/processes to find a legal basis for Processing activities. Leverage the data mapping exercise to tie into this exercise. What Can You Do?
  • 18. 18  My next presentation is on November 14th, I will be doing a tabletop exercise for incident response with HPE and others.  If you have any questions, please contact me at: Tsutomu Johnson Tjohnson@parsonsbehle.com 801.536.6903 Thank You